CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,817)
This CVE describes an OS command injection vulnerability in Fortinet FortiWLM wireless LAN management systems. Attackers can execute arbitrary command...
Oct 10, 2023This CVE describes an OS command injection vulnerability in Fortinet FortiWLM that allows attackers to execute arbitrary commands on affected systems....
Oct 10, 2023This CVE describes an OS command injection vulnerability in Fortinet FortiWLM wireless LAN management systems. Attackers can execute arbitrary command...
Oct 10, 2023CVE-2023-36618 allows authenticated low-privileged users to execute arbitrary operating system commands with root privileges on Atos Unify OpenScape S...
Oct 4, 2023This vulnerability allows authenticated attackers on ASUS RT-AX55 routers to execute arbitrary operating system commands by injecting malicious input ...
Sep 11, 2023This vulnerability allows a network-adjacent unauthenticated attacker to execute arbitrary operating system commands on affected Archer A10 routers. A...
Sep 6, 2023This CVE describes an OS command injection vulnerability in ELECOM wireless routers that allows authenticated attackers to execute arbitrary operating...
Aug 18, 2023This CVE describes a command injection vulnerability in TN-5900 Series firmware that allows remote code execution. Attackers can exploit insufficient ...
Aug 17, 2023This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Zyxel NBG6604 routers by sending specially crafted...
Aug 14, 2023This SQL injection vulnerability in ScienceLogic SL1's message viewer print feature allows attackers to execute arbitrary SQL commands by injecting ma...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1's logging export feature allows attackers to execute arbitrary SQL commands against the database ...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1 allows attackers to execute arbitrary SQL commands through the vendor_country parameter in the ve...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1's ticket watchers email feature allows attackers to execute arbitrary SQL commands by injecting m...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1's ticket queue watchers feature allows attackers to execute arbitrary SQL commands against the da...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1 allows attackers to execute arbitrary SQL commands through the 'reporter events type date' featur...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1's notes view feature allows attackers to execute arbitrary SQL commands by injecting malicious in...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1's schedule editor feature allows attackers to execute arbitrary SQL commands against the database...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1 allows attackers to execute arbitrary SQL commands through the admin dynamic app mib errors featu...
Aug 9, 2023This CVE describes a command injection vulnerability in ScienceLogic SL1's ticket report generation feature. Attackers can inject arbitrary commands i...
Aug 9, 2023This CVE describes a command injection vulnerability in ScienceLogic SL1's report download/convert feature where unsanitized user input is passed dire...
Aug 9, 2023This SQL injection vulnerability in ScienceLogic SL1's 'json walker' feature allows attackers to inject malicious SQL queries through unsanitized user...
Aug 9, 2023This CVE describes a command injection vulnerability in ScienceLogic SL1's ARP ping device tool that allows attackers to execute arbitrary commands on...
Aug 9, 2023This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on PHOENIX CONTACT WP 6xxx series web panels b...
Aug 9, 2023This vulnerability allows remote authenticated attackers to execute arbitrary operating system commands on ESDS Emagic Data Center Management Suite sy...
Aug 8, 2023This vulnerability allows remote attackers with low-privilege access to PHOENIX CONTACT WP 6xxx series web panels to escalate privileges to full devic...
Aug 8, 2023An unauthenticated LAN-based attacker can execute arbitrary OS commands on affected Zyxel network devices by sending a malicious GRE configuration whe...
Jul 17, 2023An unauthenticated command injection vulnerability in the Free Time WiFi hotspot feature of Zyxel USG FLEX and VPN series firewalls allows LAN-based a...
Jul 17, 2023This vulnerability allows an unauthenticated attacker on the local network to inject OS commands into the configuration data of affected Zyxel devices...
Jul 17, 2023This CVE describes an OS command injection vulnerability in the Milesight UR32L router's vtysh_ubus _get_fw_logs functionality. Attackers can execute ...
Jul 6, 2023This vulnerability allows remote attackers to execute arbitrary operating system commands on Maxprint Maxlink 1200G routers through the diagnostic too...
Jun 30, 2023This vulnerability in mailcow allows authenticated attackers to manipulate internal Dovecot variables by using specially crafted passwords during auth...
Jun 7, 2023This vulnerability allows authenticated users in Dolibarr to execute arbitrary code on the server by injecting PHP code with uppercase <?PHP tags inst...
May 29, 2023This CVE describes an OS command injection vulnerability in SolarView Compact devices that allows remote authenticated attackers to execute arbitrary ...
May 23, 2023This CVE describes an OS command injection vulnerability in SolarView Compact mail settings that allows authenticated remote attackers to execute arbi...
May 23, 2023CVE-2023-24805 is a command injection vulnerability in cups-filters' Backend Error Handler (beh) that allows remote code execution. Attackers with net...
May 17, 2023This vulnerability allows authenticated users to execute arbitrary commands on Advantech EKI-1524, EKI-1522, and EKI-1521 industrial switches by injec...
May 8, 2023This vulnerability in IBM TS7700 Management Interface allows authenticated users to submit specially crafted URLs that can lead to privilege escalatio...
May 4, 2023This is a post-authentication command injection vulnerability in Zyxel NBG6604 home routers. An authenticated attacker can execute arbitrary OS comman...
May 1, 2023This vulnerability allows authenticated users to inject arbitrary operating system commands in mySCADA myPRO versions 8.26.0 and prior. Attackers with...
Apr 27, 2023This vulnerability allows authenticated users in mySCADA myPRO systems to inject arbitrary operating system commands through vulnerable parameters. It...
Apr 27, 2023This vulnerability allows authenticated users of mySCADA myPRO versions 8.26.0 and prior to inject arbitrary operating system commands through vulnera...
Apr 27, 2023This is a post-authentication command injection vulnerability in Zyxel firewall CLI commands that allows authenticated attackers to execute arbitrary ...
Apr 24, 2023CVE-2023-29804 is a command injection vulnerability in WFS-SR03 v1.0.3 that allows attackers to execute arbitrary commands on affected devices via the...
Apr 14, 2023This CVE describes an OS command injection vulnerability in CONPROSYS IoT Gateway products that allows remote authenticated attackers with access to t...
Apr 11, 2023This vulnerability allows attackers on the same network to execute arbitrary code on D-Link DIR-825 routers without authentication. The flaw exists in...
Mar 29, 2023This vulnerability allows network-adjacent attackers to execute arbitrary code on D-Link DIR-825 routers without authentication. The flaw exists in th...
Mar 29, 2023This vulnerability allows attackers on the same network to execute arbitrary code on D-Link DIR-825 routers without authentication. The flaw exists in...
Mar 29, 2023This vulnerability allows attackers on the same network to execute arbitrary commands on D-Link DIR-2150 routers without authentication. The flaw exis...
Mar 29, 2023This vulnerability allows authenticated attackers to execute arbitrary shell commands with root privileges on FortiWeb web application firewalls. It a...
Feb 16, 2023This vulnerability allows authenticated attackers to execute arbitrary operating system commands on FortiWAN devices by injecting malicious arguments ...
Feb 16, 2023About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,817 CVEs classified as CWE-78, with 720 rated critical and 927 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free